which.exe

MD5:
3231a5ac99c1935b36e28f8de4159a07

SHA-1:
989da42148f651b962e57b1c7cddca54a848abf0

SHA-256:
0650a2a7a8059639f66b4f92b1f4d8a433506b170b4711af230af757ae6909c2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 3:39:37 PM UTC  (today)

File size:
66.5 KB (68,096 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
8/21/2011 5:51:37 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
768:0Jh4+/pIYolx0MtCUDL5jlUxai0J6kfON10:+1rolx0DUD1jlUxai0J64OQ

Entry address:
0x112F8

Entry point:
E9, 53, 5A, 00, 00, E9, CE, 20, 00, 00, E9, 09, 4E, 00, 00, E9, F4, 36, 00, 00, E9, FF, 51, 00, 00, E9, 0A, 4A, 00, 00, E9, 75, 4D, 00, 00, E9, 20, 57, 00, 00, E9, BB, 31, 00, 00, E9, 76, 69, 00, 00, E9, 21, 24, 00, 00, E9, EC, 69, 00, 00, E9, BD, 76, 00, 00, E9, A2, 4C, 00, 00, E9, AD, 19, 00, 00, E9, 98, 1A, 00, 00, E9, 31, 76, 00, 00, E9, 4C, 51, 00, 00, E9, B1, 76, 00, 00, E9, 04, 54, 00, 00, E9, 6F, 48, 00, 00, E9, 3E, 6C, 00, 00, E9, 75, 27, 00, 00, E9, 00, 53, 00, 00, E9, DB, 0B, 00, 00, E9, 96, 1E...
 
[+]

Entropy:
4.6527

Developed / compiled with:
Microsoft Visual C++ 8.0 (Debug)

Code size:
44 KB (45,056 bytes)

The file which.exe has been seen being distributed by the following URL.

Scan which.exe - Powered by Reason Core Security